Potential problems with third-party Web plugins
#1
Information 
Quote:
[Image: dangerous-plugins-featured.jpg]

Online stores, information portals, and other resources are often based on platforms that provide developers with a set of ready-made tools. Our blog, for example, is built along those lines. Features are usually made available in the form of plugins, allowing users to add them as required. On the one hand, it’s a convenient system that avoids forcing developers to reinvent the proverbial wheel every time they need a particular tool or feature. On the other hand, the more third-party developments on your website, the higher the risk that something might go awry.

The problem with plugins


A plugin is a small software module that either adds to or improves a website’s functionality. There exist plugins that display social network widgets, harvest statistics, and create surveys and other types of content, to name just a few.

If you connect a plugin to your website’s engine, it runs automatically and bothers you only if an error occurs in its operation — that is, if somebody notices the error. Therein lurks the danger of such modules: If the creator abandons their plugin or sells it to another developer, you will likely not notice a thing.

Leaky plugins

Plugins that have not been updated for years are likely to contain unpatched vulnerabilities that could be exploited to take control of a website or download onto it a keylogger, cryptocurrency miner, or whatever the cybercriminals fancy.

Even when updates are available, website owners often overlook them, and vulnerable modules can remain active years after support for them is withdrawn.

Sometimes plugin creators patch vulnerabilities, but for whatever reason the patches are not automatically installed. For example, in some cases module authors simply forget to change the version number in the update. As a result, clients who relied on automatic updating instead of checking for updates manually were left with outdated plugins.

Plugin substitution

Some website content management platforms block the download of modules that are no longer supported. However, it is not possible for a developer or platform to delete vulnerable plugins from users’ websites; that could cause disruption or worse.

What’s more, abandoned plugins might be stored not on the platform itself, but on publicly available services. When the creator discontinues support or deletes a module, your website continues to access the container in which it was located. But cybercriminals can easily capture or clone this abandoned container, and force the resource to download malware instead of the plugin.

That is precisely what happened with the New Share Counts tweet counter, hosted in Amazon S3 cloud storage. When support for the plugin was withdrawn, the developer posted a message to that effect on its website, but more than 800 clients did not read it.

A while later, the plugin writer closed the container on Amazon S3, and cybercriminals pounced. They created storage with the exact same name and placed inside it a malicious script. Websites still using the plugin began to load the new code, which redirected users to a phishing resource promising a prize for taking a survey, instead of the tweet counter.
Continue Reading
Reply


Messages In This Thread
Potential problems with third-party Web plugins - by harlan4096 - 06 April 19, 07:01

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Android Security Bulletin—March 2026
Android Security B...harlan4096 — 11:13
Qualcomm unveils Wi-Fi 8 chip designed t...
Qualcomm has commi...harlan4096 — 11:10
Adobe Acrobat Reader DC 2025.001.21265
Adobe Acrobat Read...harlan4096 — 11:07
uBOLite 2026.301.2014 (already released ...
uBOLite 2026.301.2...harlan4096 — 11:06
NVIDIA GeForce Game Ready 595.71 driver
Highlights  Gam...harlan4096 — 11:05

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (43)slavrProck
avatar (45)Tyesharaike
avatar (49)TomeRerla
avatar (45)walllMIZ
avatar (41)oconyho
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (45)tukraNax
avatar (41)RichardCisee
avatar (40)ebenofit
avatar (38)ykazawu
avatar (41)ARYsahulatbazar

[-]
Online Staff
There are no staff members currently online.

>